{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/gst-plugins-ugly/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.1,"id":"CVE-2026-19389"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["gst-plugins-ugly"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["GStreamer"],"content_html":"\u003cp\u003eSecurity researchers identified multiple integer overflow and underflow vulnerabilities within the GStreamer 'gst-plugins-ugly' ASF demuxer (asfdemux). The flaws reside in the component responsible for parsing ASF, WMV, and WMA header objects. Specifically, the demuxer fails to perform adequate validation on length and size values provided within the media file structure.\u003c/p\u003e\n\u003cp\u003eWhen processing a maliciously crafted media file, these unvalidated fields bypass internal bounds checks, leading to out-of-bounds heap reads. Depending on the target application's configuration and memory layout, this vulnerability can be leveraged to trigger a denial of service through an application crash or to leak sensitive memory contents to an attacker. The scope of impact includes any software utilizing the 'gst-plugins-ugly' plugin for media processing, which is cross-platform and common across many Linux distributions, desktop applications, and embedded media systems.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability poses a significant risk to applications that automatically process or preview untrusted media files, such as media players, browser-based media engines, or file-indexing services. Successful exploitation can lead to a crash of the media processing service (Denial of Service) or potential information disclosure. While the primary impact noted is DoS, out-of-bounds heap reads are often precursors to more complex exploitation chains aimed at code execution.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate GStreamer 'gst-plugins-ugly' to the latest vendor-provided version that includes fixes for CVE-2026-19389.\u003c/li\u003e\n\u003cli\u003eAudit applications that process external media files to determine if they rely on the 'gst-plugins-ugly' package.\u003c/li\u003e\n\u003cli\u003ePrioritize patching for internet-facing services or applications that automatically scan/process media attachments, as these represent the most likely attack vector.\u003c/li\u003e\n\u003cli\u003eMonitor logs for recurring crashes of media-processing services, which may indicate exploitation attempts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-10T03:50:53Z","date_published":"2026-08-10T03:50:53Z","id":"https://feed.craftedsignal.io/briefs/2026-08-gstreamer-overflow/","summary":"Multiple integer overflow and underflow vulnerabilities in the GStreamer gst-plugins-ugly ASF demuxer allow remote attackers to cause application crashes or information disclosure via crafted media files.","title":"Integer Overflow Vulnerability in GStreamer gst-plugins-ugly","url":"https://feed.craftedsignal.io/briefs/2026-08-gstreamer-overflow/"}],"language":"en","title":"CraftedSignal Threat Feed - Gst-Plugins-Ugly","version":"https://jsonfeed.org/version/1.1"}